802.1x Commands
765
Guest VLAN
The Guest VLAN feature allows a PowerConnect switch to provide a
distinguished service to unauthenticated users (not rogue users who fail
authentication). This feature provides a mechanism to allow visitors and
contractors to have network access to reach external network with no ability
to surf internal LAN.
When a client that does not support 802.1X is connected to an unauthorized
port that is 802.1X-enabled, the client does not respond to the 802.1X
requests from the switch. Therefore, the port remains in the unauthorized
state, and the client is not granted access to the network. If a guest VLAN is
configured for that port, then the port is placed in the configured guest
VLAN, and the port is moved to the authorized state, allowing access to the
client.
802.1x Monitor Mode
Monitor mode is a special mode that can be enabled in conjunction with
Dot1x authentication. It allows network access even in case where there is a
failure to authenticate but logs the results of the authentication process for
diagnostic purposes. The exact details are described in the below sections.
The main aim of the monitor mode is to provide a mechanism to the operator
to be able to identify the short-comings in the configuration of a Dot1x
authentication on the switch without affecting the network access to the
users of the switch.
There are three important aspects to this feature after activation:
1
To allow successful authentications using the returned information from
authentication server.
2
To provide a mechanism to report unsuccessful authentications without
negative repercussions to the user due to operator errors or failure cases
from the Authentication server or supplicants.
3
To accurately report the data received from the successful and
unsuccessful operations so that the operator can make the appropriate
changes or learn where the problem areas are.
The monitor mode can be configured globally on a switch. If the switch fails
to authenticate the user for any reason (say RADIUS access reject from
RADIUS server, RADIUS timeout, or the client itself is Dot1x unaware), the
2CSPC4.XModular-SWUM200.book Page 765 Thursday, March 10, 2011 11:18 AM
Summary of Contents for PowerEdge M420
Page 161: ...Command Groups 161 ...
Page 162: ...162 Command Groups ...
Page 216: ...216 Layer 2 Commands ...
Page 290: ...290 Auto VoIP Commands ...
Page 310: ...310 Data Center Bridging Commands ...
Page 316: ...316 DHCP Layer 2 Relay Commands Example console config dhcp l2relay vlan 10 340 345 ...
Page 324: ...324 DHCP Management Interface Commands ...
Page 340: ...340 DHCP Snooping Commands ...
Page 354: ...354 Dynamic ARP Inspection Commands ...
Page 405: ...Ethernet Configuration Commands 405 Name test ...
Page 406: ...406 Ethernet Configuration Commands ...
Page 426: ...426 Ethernet CFM Commands ...
Page 486: ...486 IPv6 Access List Commands ...
Page 497: ...IPv6 MLD Snooping Commands 497 Vlan Ipv6 Address Ports ...
Page 498: ...498 IPv6 MLD Snooping Commands ...
Page 512: ...512 IP Source Guard Commands ...
Page 524: ...524 iSCSI Optimization Commands ...
Page 532: ...532 Link Dependency Commands ...
Page 572: ...572 Port Aggregator Commands ...
Page 756: ...756 VLAN Commands ...
Page 762: ...762 Voice VLAN Commands ...
Page 796: ...796 802 1x Commands ...
Page 798: ...798 Layer 3 Commands ...
Page 842: ...842 DHCP Server and Relay Agent Commands ...
Page 868: ...868 DVMRP Commands ...
Page 888: ...888 IGMP Commands ...
Page 896: ...896 IGMP Proxy Commands ...
Page 938: ...938 IP Routing Commands ...
Page 1012: ...1012 IPv6 Routing Commands ...
Page 1016: ...1016 Loopback Interface Commands ...
Page 1048: ...1048 Multicast Commands ...
Page 1064: ...1064 IPv6 Multicast Commands RP Address 3001 1 origin BSR ...
Page 1142: ...1142 OSPF Commands ...
Page 1202: ...1202 OSPFv3 Commands ...
Page 1212: ...1212 Router Discovery Protocol Commands ...
Page 1228: ...1228 Routing Information Protocol Commands ...
Page 1260: ...1260 Virtual Router Redundancy Protocol Commands ...
Page 1262: ...1260 Utility Commands ...
Page 1272: ...1270 Auto Install Commands ...
Page 1306: ...1304 Captive Portal Commands ...
Page 1316: ...1314 CLI Macro Commands ...
Page 1334: ...1332 Clock Commands ...
Page 1340: ...1338 Command Line Configuration Scripting Commands ...
Page 1362: ...1360 Configuration and Image File Commands ...
Page 1363: ...Configuration and Image File Commands 1361 ...
Page 1364: ...1362 Configuration and Image File Commands ...
Page 1412: ...1408 Password Management Commands ...
Page 1436: ...1432 RMON Commands ...
Page 1476: ...1472 Sflow Commands ...
Page 1536: ...1532 Syslog Commands ...
Page 1602: ...1598 Telnet Server Commands ...
Page 1604: ...1600 Terminal Length Commands ...
Page 1618: ...1614 User Interface Commands ...
Page 1638: ...1634 Web Server Commands ...
Page 1680: ...1676 Appendix A List of Commands ...
Page 1681: ......
Page 1682: ...www dell com support dell com Printed in the U S A ...